"broke into almost all of our classified systems, not in weeks, but in hours." — Sen. Mark Warner
Export limits imposed by the White House on Anthropic
The Trump administration this month imposed export controls on Anthropic, citing national-security concerns, and the company responded by pulling back release of its most advanced models, including Mythos 5 and Fable 5. That policy decision immediately constrained how and where the company could distribute its frontier models and produced ripple effects inside U.S. cyber agencies.
Immediate operational impact on parts of the NSA
According to two people familiar with the matter, some analysts at the National Security Agency were notified on Friday that they would lose access to Anthropic’s Mythos model. One of those people said the agency may still be able to use earlier versions of the technology under prior arrangements, while both sources — granted anonymity to speak freely — confirmed that access to the latest releases had been curtailed.
The change could disrupt NSA work that had been exploring whether advanced models can help identify software weaknesses. Reporting by the New York Times followed public attention after Sen. Mark Warner relayed a remark he attributed to NSA leadership; the Economist later published an explanation that the specific Mythos work Warner cited was part of a controlled red-teaming effort.
Project Glasswing, red teams, and Mythos Preview
Project Glasswing, launched in April, provided select security researchers and organizations early access to Mythos Preview. Anthropic described that Preview as showing capabilities that could reshape cybersecurity. The company later expanded the program to roughly 150 organizations in more than 15 countries after weeks of coordination with government, industry and open-source partners.
An official cited by the Economist told the publication that the agency’s red teams no longer have access to Mythos because their authority to use it came through Project Glasswing. Red-teaming efforts are controlled security exercises in which authorized testers attempt to break into or stress-test systems so organizations can find and fix vulnerabilities before real attackers exploit them.
Five Eyes warning on frontier AI and the cyber timeline
On Monday, the Five Eyes intelligence alliance warned that frontier AI models could sharply change the cyber threat landscape within months, not years, by enabling attackers and defenders to move faster. That advisory highlights why access to advanced models — and limits on that access — matters to both offensive testing and defensive preparations.
What this means for cyber defenders, policymakers, and the NSA
- Cyber defenders and red teams: Organizations that were using Project Glasswing access for authorized testing now face curtailed tooling; defenders will have to know whether earlier versions available under prior agreements are sufficient for red-team exercises and vulnerability discovery.
- Policymakers and regulators: The White House decision to restrict exports of Mythos 5 and Fable 5 reflects a national-security judgment that has immediate operational consequences and has "raised questions about how U.S. cyber agencies will continue using the technology," according to reporting grounded in the same disclosures that described lost access at the NSA.
- The NSA and other U.S. cyber agencies: Some staff have been notified they will lose Mythos access, though the agency may still retain some capacity through earlier versions under prior arrangements. The loss of Project Glasswing authority for red teams, specifically, removes a pathway previously used for controlled, internal security testing.
The sequence — a White House export restriction, Anthropic’s pullback of Model releases, Project Glasswing’s curtailment for red teams, and a Five Eyes alert about timing — connects policy and practice in real time. The reporting shows that the controls were intended to address national-security concerns but that they have also narrowed tools available to authorized testers inside the U.S. security community. It leaves a concrete, near-term question unanswered by the record so far: can prior arrangements and earlier model versions sustain the red-teaming and vulnerability work the NSA and its partners were conducting, even as governments warn that frontier AI could reshape the cyber landscape within months?




